Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Lador
Technical ID: osx.lador
APT GROUP
Malware family identifying osx.lador. Origin and technical characteristics tracked via Malpedia.
Kuiper
Technical ID: osx.kuiper
APT GROUP
Malware family identifying osx.kuiper. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.komplex. Origin and technical characteristics tracked via Malpedia.
Also known as: SedUploader • JHUHUGIT • JKEYSKW
Kitmos
Technical ID: osx.kitmos
APT GROUP
Malware family identifying osx.kitmos. Origin and technical characteristics tracked via Malpedia.
Also known as: KitM
KeySteal
Technical ID: osx.keysteal
APT GROUP
According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
Keydnap
Technical ID: osx.keydnap
APT GROUP
Malware family identifying osx.keydnap. Origin and technical characteristics tracked via Malpedia.
KeRanger
Technical ID: osx.keranger
APT GROUP
Malware family identifying osx.keranger. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.kandykorn. Origin and technical characteristics tracked via Malpedia.
JokerSpy
Technical ID: osx.jokerspy
APT GROUP
Malware family identifying osx.jokerspy. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Patrick Wardle, this malware persists a python script as a cron job.
Steps:
1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'.
2. Appends its new job to this file.
3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.
APT GROUP
Malware family identifying osx.interception. Origin and technical characteristics tracked via Malpedia.
APT GROUP
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic.
Variants in GO.
iMuler
Technical ID: osx.imuler
APT GROUPespionageadvanced
The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running dispute over the Diaoyu Islands; an array of erotic pictures; or images of Tibetan organisations. It consisted of two stages: Revir was the dropper/downloader and Imuler was the backdoor capable of the following operations:
- capture screenshots
- exfiltrate files to a remote computer
- send various information about the infected computer
- extract ZIP archive
- download files from a remote computer and/or the Internet
- run executable files
Also known as: Revir
HZ RAT
Technical ID: osx.hz_rat
APT GROUP
Malware family identifying osx.hz_rat. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.hloader. Origin and technical characteristics tracked via Malpedia.
HiddenLotus
Technical ID: osx.hiddenlotus
APT GROUP
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising itself as a document - in this case, an Adobe Acrobat file.
APT GROUP
Malware family identifying osx.golangghost. Origin and technical characteristics tracked via Malpedia.
Gmera
Technical ID: osx.gmera
APT GROUP
According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users.
Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.
Also known as: StockSteal • Kassi
GIMMICK
Technical ID: osx.gimmick
APT GROUP
This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity. This malware is a file-based C2 implant used by Storm Cloud.
FULLHOUSE
Technical ID: osx.fullhouse
APT GROUP
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.
FruitFly
Technical ID: osx.fruitfly
APT GROUP
Malware family identifying osx.fruitfly. Origin and technical characteristics tracked via Malpedia.
Also known as: Quimitchin
APT GROUP
Malware family identifying osx.frostyferret. Origin and technical characteristics tracked via Malpedia.
FrigidStealer
Technical ID: osx.frigid_stealer
APT GROUP
According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
APT GROUP
Malware family identifying osx.friendlyferret. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.flexibleferret. Origin and technical characteristics tracked via Malpedia.
FlashBack
Technical ID: osx.flashback
APT GROUP
Malware family identifying osx.flashback. Origin and technical characteristics tracked via Malpedia.
Also known as: FakeFlash
FinFisher
Technical ID: osx.finfisher
APT GROUP
Malware family identifying osx.finfisher. Origin and technical characteristics tracked via Malpedia.
FailyTale
Technical ID: osx.failytale
APT GROUP
Malware family identifying osx.failytale. Origin and technical characteristics tracked via Malpedia.
EvilQuest
Technical ID: osx.evilquest
APT GROUPfinancialhigh
According to PcRisk, EvilQuest (also known as ThiefQuest) is like many other malicious programs of this type - it encrypts files and creates a ransom message. In most cases, this type of malware modifies the names of encrypted files by appending certain extensions, however, this ransomware leaves them unchanged.
It drops the "READ_ME_NOW.txt" in each folder that contains encrypted data and displays another ransom message in a pop-up window. Additionally, this malware is capable of detecting if certain files are stored on the computer, operates as a keylogger, and receives commands from a Command & Control server.
Also known as: ThiefQuest
EvilOSX
Technical ID: osx.evilosx
APT GROUP
Malware family identifying osx.evilosx. Origin and technical characteristics tracked via Malpedia.
ElectroRAT
Technical ID: osx.electro_rat
APT GROUP
According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows, MacOS, and Linux users. Cyber criminals behind ElectroRAT target mainly cryptocurrency users. This RAT is distributed via the trojanized Jamm, eTrader, and DaoPoker applications.
Eleanor
Technical ID: osx.eleanor
APT GROUPespionageadvanced
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter. This application bundle wraps a shell script that uses Dropbox name as a disguise and installs three components: a hidden Tor service, a Pastebin agent and a web service with a PHP-based graphical interface.
The Tor service transforms the victim’s computer into a server that provides attackers with full anonymous access to the infected machine via Tor-generated address.
The Pastebin agent uploads the address in encrypted form to the Pastebin website where the attackers can obtain it.
The web service is the main malicious component that provides the attackers with the control over the infected machine. After successful authentication, the interface offers several control panels to the attackers, allowing them to do the following actions:
- Managing files
- Listing processes
- Connecting to various database management systems such as MySQL or SQLite
- Connecting via bind/reverse shell
- Executing shell command
- Capturing and browsing images and videos from the victim’s webcam
- Sending emails with an attachment
EggShell RAT
Technical ID: osx.eggshell_rat
APT GROUP
Malware family identifying osx.eggshell_rat. Origin and technical characteristics tracked via Malpedia.
Dummy
Technical ID: osx.dummy
APT GROUP
Malware family identifying osx.dummy. Origin and technical characteristics tracked via Malpedia.
Dockster
Technical ID: osx.dockster
APT GROUP
Malware family identifying osx.dockster. Origin and technical characteristics tracked via Malpedia.
DazzleSpy
Technical ID: osx.dazzle_spy
APT GROUP
Malware family identifying osx.dazzle_spy. Origin and technical characteristics tracked via Malpedia.
DarthMiner
Technical ID: osx.darthminer
APT GROUP
Malware family identifying osx.darthminer. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely.
Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.
Cthulhu Stealer
Technical ID: osx.cthulhu_stealer
APT GROUP
Malware family identifying osx.cthulhu_stealer. Origin and technical characteristics tracked via Malpedia.
Crossrider
Technical ID: osx.crossrider
APT GROUP
Malware family identifying osx.crossrider. Origin and technical characteristics tracked via Malpedia.